Documentation

Ongoing operations

Automated access reviews

ISO 27001 Annex A controls A.5.15 through A.5.18 cover access control, identity management and the review of access rights. The identity audit scan engine checks a connected identity provider directly for the two failures that actually cause access-control incidents: accounts without multi-factor authentication, and dormant or former-employee accounts nobody remembered to revoke.

Transcript

Access reviews are not a box-ticking exercise under ISO 27001. Annex A controls A.5.15 through A.5.18 require you to actually confirm access rights match business need, not just assert that they do.

A scan result dated today is worth more than a policy document written two years ago. The identity audit engine checks a connected identity provider directly, for accounts without multi-factor authentication, and for dormant or former-employee accounts that were never revoked.

Setting one up is the same as any other connector: a name, the identity provider, and its credentials. Google Workspace, GitHub organisations and Microsoft 365 are all real, working connector types today.

Each finding attaches directly to the connector, dated and severity-rated, so "we reviewed access" becomes "here is exactly what we found, and when".

That evidence feeds a real obligation. ISO 27001 A.5.15 flips to completed automatically once a current review confirms multi-factor authentication is enforced and no dormant accounts remain. No manual checkbox, no separate report to write.

Why this is required

A.5.18 requires access rights to be provisioned, reviewed, modified and removed according to policy. "Reviewed" is the word that is hardest to evidence honestly: a policy document describing a review process is not the same as proof the review happened, on a specific date, against real accounts.

Former-employee and dormant accounts are also one of the most common real-world entry points for account takeover, which is why A.5.16 and A.5.17 exist alongside A.5.18 rather than access rights being covered by a single control.

What EuroCompliant does

A scan connector points the identity audit engine at a real identity provider: Google Workspace, a GitHub organisation, or Microsoft 365. Each connector type has its own real credential fields, following the same connector model automated scanning already uses for infrastructure sources.

Findings are dated and severity-rated: an account without multi-factor authentication enforced, or an account with no sign-in activity past a threshold, each attach to the connector as a specific, timestamped result rather than a general assertion.

That evidence feeds a real obligation automatically. ISO 27001 A.5.15 flips to completed once a current review confirms multi-factor authentication is enforced and no dormant accounts remain, and flips back if a new finding appears, so the obligation status always reflects what was actually found, not what was found once.

Walking through it

1

Connect an identity provider

Google Workspace, a GitHub organisation, or Microsoft 365, each with its own real credential fields.

Open /settings/scan-connectors →
2

Run or schedule the identity audit scan

On demand for a one-off review, or on a recurring schedule so the evidence stays current rather than aging.

Open /scans →
3

Review findings by severity

Missing multi-factor authentication and dormant accounts are dated findings attached directly to the connector.

Open /scans →

The law

Frequently asked

Does this replace a manual access review entirely?

It replaces the evidence-gathering part. A person still decides whether a flagged account's access is actually still needed; the scan tells you which accounts need that decision made, and when it was last checked.

What happens if I don't have a real identity provider connected yet?

The ISO 27001 A.5.15 obligation stays in its not-started state until a connector exists. It does not fail or block anything else in the platform.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial